Complex systems containing many system elements and dependencies are highly vulnerable to attack and cascading failure. It is, therefore, necessary to strengthen the resilience of such systems so as to not only protect against disruption, but to respond and quickly recover from disruption as well. However, quantifying resilience of interdependent systems and particularly cyber systems is an open problem given system complexity. In this chapter, we initiate the study with the concept of system non-resilience, which is a novel steppingstone towards ultimately tackling the problem of resilience. Specifically, we present a methodology and accompanying metrics for quantifying the non-resilience of cyber-enabled systems (which are broadly defined to include critical infrastructures, networks, and computers) and for hardening such systems by reducing their non-resilience. We demonstrate the usefulness of the methodology and metrics via a case study on a space infrastructure, by showing how to quantify and employ countermeasures to reduce its non-resilience. This concept of system non-resilience can also be adapted to other complex cyber systems, helping inform decision-makers of their non-resilience and how they may best reduce it.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Quantifying and Reducing System Non-Resilience: Methodology, Metrics, and Case Study

  • Jose Luis Castanon Remy,
  • Ekzhin Ear,
  • Shouhuai Xu

摘要

Complex systems containing many system elements and dependencies are highly vulnerable to attack and cascading failure. It is, therefore, necessary to strengthen the resilience of such systems so as to not only protect against disruption, but to respond and quickly recover from disruption as well. However, quantifying resilience of interdependent systems and particularly cyber systems is an open problem given system complexity. In this chapter, we initiate the study with the concept of system non-resilience, which is a novel steppingstone towards ultimately tackling the problem of resilience. Specifically, we present a methodology and accompanying metrics for quantifying the non-resilience of cyber-enabled systems (which are broadly defined to include critical infrastructures, networks, and computers) and for hardening such systems by reducing their non-resilience. We demonstrate the usefulness of the methodology and metrics via a case study on a space infrastructure, by showing how to quantify and employ countermeasures to reduce its non-resilience. This concept of system non-resilience can also be adapted to other complex cyber systems, helping inform decision-makers of their non-resilience and how they may best reduce it.